← Vulnerability feed

Vulnerability record · CVE-2023-0126 · published 19 January 2023

CVE-2023-0126: SonicWall SMA1000 firmware pre-auth path traversal file disclosure

Sonicwall · Sma1000 Firmware

SMA1000 firmware version 12.4.2 contains a pre-authentication path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files and directories outside the web root. Because no credentials or user interaction are required and the exposed data is rated high confidentiality impact, internet-facing SMA1000 appliances are a direct target for credential and configuration theft.

7.5 CVSS 3.1 High EPSS 73% · top 0.6% CWE-22 · Path traversal
7.5CVSS 3.1 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable file disclosure on an internet-facing appliance with a very high EPSS score, though no KEV listing or confirmed exploit is recorded.

What it is

SMA1000 firmware version 12.4.2 contains a pre-authentication path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files and directories outside the web root. Because no credentials or user interaction are required and the exposed data is rated high confidentiality impact, internet-facing SMA1000 appliances are a direct target for credential and configuration theft.

Impact

An attacker gains read access to arbitrary files on the appliance, which can expose credentials, session data and configuration secrets. There is no integrity or availability impact per the CVSS vector; the loss is disclosure only.

Attack surface

Reachable over the network via HTTP/HTTPS on the SMA1000 management or web interface (AV:N, PR:N, UI:N). No authentication and no user interaction are needed, so any host that can reach the appliance can attempt it.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware association is recorded in this data, but EPSS is very high at 0.727 (99.4th percentile), indicating strong predicted exploitation activity. The only references are the vendor advisory, so confirmed in-the-wild use is not established here.

What to do

  • Upgrade SMA1000 firmware to the fixed release named in SonicWall advisory SNWLID-2023-0001; 12.4.2 is the affected version.
  • Restrict network access to the SMA1000 web interface to trusted management networks or VPN, and remove direct internet exposure where possible.
  • Rotate credentials, certificates and any secrets stored on or managed through the appliance, since file disclosure may have exposed them.
  • Review appliance logs for traversal-style requests and treat any prior suspicious access as a potential compromise.

Detection

  • Search web/proxy logs for path traversal patterns such as ../, ..%2f, %2e%2e%2f and encoded variants in requests to SMA1000 endpoints.
  • Alert on requests to the SMA1000 interface from unexpected source IPs or geographies, especially unauthenticated requests returning 200 with file-like content.
  • Monitor for access to sensitive paths outside the web root (configuration, credential or key files) in appliance and file access logs.
  • Correlate any observed traversal attempts with subsequent authentication anomalies or new administrative sessions on the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-0126 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed7.8CVE-2021-33909Linux kernel integer overflow vulnerabilityfs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow…EPSS 9.7%7.5CVE-2020-5129Sonicwall sma1000 firmware http request smuggling vulnerabilityA vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leads to Den…EPSS 1.3%7.2CVE-2025-2170Sonicwall sma1000 firmware server-side request forgery (ssrf) vulnerabilityA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions co…EPSS 0.34%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed

Source: NIST National Vulnerability Database (record CVE-2023-0126), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.